External Security Snapshot / from £149

A 48-hour external security snapshot for visible web, DNS and email trust signals.

A fixed-scope, low-touch external review of public-facing web, DNS, email trust and exposed security signals. Delivered as a written report with priority, evidence and plain-English remediation.

From £149 / Written scope first / No intrusive testing / Not a full penetration test
Findings register
External posture68
48-hour delivery where suitable
0Critical
1High
6Medium
8Info
HighDMARC policy does not enforce rejectionEmail
MediumMissing strict transport policyTLS
MediumAdmin surface visible to public internetLogin
InfoTechnology stack visible in headersWeb
Remediation checklist

Owner, priority, recommended fix, validation step and business impact for each finding.

£149 starting pointClear fixed-scope external review.
Written reportEvidence, impact and recommended fixes.
No account accessNo passwords or 2FA codes requested.
Scope reassurancePermission and target boundaries confirmed first.
What is included

Focused checks across the visible external surface.

The snapshot is designed for teams that need a practical external view quickly, without intrusive testing or enterprise consultancy overhead.

Web and TLS

Headers, certificates and browser hardening

HSTS, CSP, frame control, referrer policy, transport configuration and common public security headers.

DNS and mail

Domain and email trust posture

SPF, DKIM, DMARC, CAA and public DNS signals that affect spoofing resistance and trust.

Exposure

Login, CMS and staging surfaces

Visible admin routes, WordPress surface, staging clues and public technology signals that may need tightening.

Sample deliverable
Evidence-led security report
Fictional sample
Scope
Web
6
DNS
4
Mail
2
Finding: DMARC policy in monitor modePriority, business impact, observed record and recommended next step are shown together.
Evidence
DNS record snapshot and affected domain.
Remediation
Suggested policy path and validation step.
What you receive
Prioritised, readable and scoped first.

No fake dashboards or stock proof. The output is a practical written snapshot with evidence, severity, remediation and boundaries clear enough for a founder, agency or technical team to act on.

  • Findings grouped by impact and effort.
  • Plain-English notes beside technical evidence.
  • Retest guidance included where useful.
Scope boundaries

Clear about what this is not.

The External Security Snapshot is a lightweight external review. It is intentionally narrow, lawful and non-intrusive.

Included
  • Public-facing checks
  • Written report
  • Prioritised remediation
  • Scope agreed first
  • Plain-English findings
Not included
  • Full penetration test
  • Compliance certification
  • Exploitation attempts
  • Brute force or destructive testing
  • Testing systems you are not authorised to request
Sample PDF

Fictional SaaS / API Readiness Snapshot

Shows document control, limitations, severity, evidence and action planning.

No client data. Fictional sample only.
Report preview

Built to help teams act.

Each finding is written with enough evidence to understand the issue and enough practical guidance to fix or delegate it without translating security jargon.

  • Executive summary and priority list
  • Finding table with severity and affected area
  • Evidence snippets and validation notes
  • Recommended remediation order
Process

Permission first. Review second.

01

Send the domain

Use the form with the domain, company and context for the review.

02

Scope confirmed

The exact public-facing target and boundaries are agreed in writing.

03

Payment after approval

Payment link or invoice is sent only after written scope approval.

04

Report delivered

You receive the written report with findings and remediation priorities, usually within 48 hours where scope is suitable.

FAQ

Common questions

Is this a penetration test?
No. It is a lightweight external snapshot, not a full penetration test, red-team exercise or compliance audit.
Do you need passwords?
No. Passwords, 2FA codes and sensitive credentials are not requested for this service.
Can agencies request this before handover?
Yes, where they are authorised to commission the review. The authorisation and target scope are confirmed before any work begins.
Will this prove we are secure?
No review can prove that. This snapshot identifies visible external gaps and prioritises practical remediation. It is not a guarantee or certificate.
Request the £149 snapshot

Send the domain and context.

No commitment at this stage. I will reply with scope, timing and next steps if the request fits the snapshot model.

£149
No intrusive testing / No passwords / Written scope first / Client reports confidential by default

Do not submit passwords, credentials, secrets or sensitive information. Form submissions are processed via Formspree so we can respond to your enquiry. By submitting, you confirm you are authorised to request a review for the website, product or brand provided.